fingerprint-nextjs

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for managing API keys using Next.js environment variable conventions, correctly separating public keys from server-side secrets to prevent accidental exposure, as documented in SKILL.md and implemented in snippets/fingerprint-server.ts.
  • [EXTERNAL_DOWNLOADS]: The skill references official Node.js and React SDKs from the vendor for identification and verification tasks, which are standard and expected dependencies for this integration.
  • [INDIRECT_PROMPT_INJECTION]: The server-side verification logic in snippets/fingerprint-server.ts correctly validates the event_id received from the client by performing comprehensive checks against the Fingerprint Server API, including bot detection and replay protection, ensuring untrusted input is properly vetted before any sensitive actions proceed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:25 PM
Security Audit — agent-trust-hub — fingerprint-nextjs